SecOps Engineer III

ACV Auctions
Toronto, ON Full Time
POSTED ON 12/10/2021 CLOSED ON 12/26/2021

What are the responsibilities and job description for the SecOps Engineer III position at ACV Auctions?

ACV’s mission is to build and enable the most trusted and efficient digital marketplaces for buying and selling used vehicles with transparency and comprehensive data that was previously unimaginable. We are powered by a combination of the world’s best people and the industry’s best technology.  At ACV, we are driven by an entrepreneurial spirit and rewarded with a work environment that enables each Teammate to impact the company from day one. ACV’s network of brands includes ACV Auctions, ACV Transportation and ACV Capital within its Marketplace Products as well as True360 and Data Services.

ACV Auctions is looking for a SecOps Engineer. We are building a layered Security approach which means the SecOps Engineer will need to work hand in hand with teams such as Infrastructure, AppSec, Detection and Response, Development Teams and Internal Audit. In this role you will be responsible for driving Identity and Access Management best practices to include SSO, MFA, RBAC, Password Management and application configuration. The SecOps Engineer will also be responsible for identifying, evaluating, and participating in decision making around new and emerging Identity and Access management technologies and should be able to support other areas of Information Security as needed. The individual in this role will be working to enhance and strengthen other security controls within our environment as a whole, such as: anti-phishing gateways, EDR, AV, firewalls, IDS/IPS systems and AWS Security Hub. Not only will this role focus on growing ACV's capabilities but will also focus on developing/training other teammates.

What you will do:

  • Deep understanding of Identity and Access management and the tool’s therein
  • Able to work with vendors and manage PoC's
  • Perform business use case analysis to implement identity and access management solutions
  • Identify required attributes, customizing login pages and implement security policies
  • Follow SDLC, change management and document the procedures on Trusted Identity solutions to meet compliance requirements
  • Anticipate, identify, track and resolve technical issues
  • Establish repeatable processes for Access Management
  • Lead the Trusted Identity team in implementing scalable access management and identity lifecycle processes
  • Work closely with business, application, and solution owners to ensure user and role definitions and associated access rights are appropriately
  • Assist in the support of the role-based access control (RBAC) model and maintain role-based access control documentation for operational processes
  • Create and implement automated processes that reduce manual efforts and increase overall efficiency and scalability
  • Manage Security Alerts and provide Incident Response support services, it's not expected someone knows everything but this person should be able to identify and perform triage to resolve a Security Incident
  • Contribute to the development, improvement and operational management of Security Operations, Monitoring and Incident Response practices, processes and solutions
  • Manage, Engineer and maintain other security SaaS applications such as anti-phishing, EDR, or logging tools as require
  • Able to assist in employee trainings , such as creating webinars, create “how-to” tech articles, etc
  • Helping to create and understand an escalation support framework. With the ability track and manage support requests from our partners internally and externally,

What you will need:

  • Practical hands-on experience engineering and implementing data security controls in cloud environments including databases, datastores and SaaS platforms
  • Extensive and demonstrated experience in end-to-end deployment of identity and access management tools
  • Overall understanding of Security Domains, Compliance Requirements, and Risk Management Practices
  • Experience with Okta planning, implementation and operations
  • Experience with Cloud technologies (Google Cloud Platform, Azure or AWS)
  • Understanding of their Identity concepts such as Privileged Account Management and Life Cycle Management 
  • General understanding DevOps practices
  • Understanding of building and making tools for our partners, how do we make something into a service? how do we navigate with them
  • Comfortable reading python code and writing basic scripts, or using Low Code / No Code SOAR tools
  • Knowledge of AWS including but not limited to S3, Lambda, RDS, EC2 and AWS Security Center
  • Building and implementing security tools such as anti-phishing, EDR, or EMM/MDM tools 
  • Understanding of TCP/IP Networking including knowledge of Protocols and Services
  • Overall understanding of the Security domain, compliance, business, risk, ops etc ALONG with its application to the business 
  • Excellent communication, interpersonal and leadership skills, with the ability to interact with staff at all levels.
  • Proven ability to be agile and work effectively in a dynamic environment. 
  • Demonstrated ability to perform under pressure and respond rapidly to emerging incidents and situations.
  • Excellent coordination, project management, and organization skills and comfortable with multi-tasking in a high-energy environment. 
  • Should be a creative and analytical problem solver with a passion to provide excellent customer service

What we offer:

  • Comprehensive benefits offerings for benefits eligible Teammates.
  • Unique culture that truly values each and every Teammate.
  • Career development and Future Growth Opportunities.

At ACV, we are committed to an inclusive culture in which every individual is welcomed and empowered to celebrate their true selves. We achieve this by fostering a work environment of acceptance and understanding that is free from discrimination. ACV is committed to being an equal opportunity employer regardless of sex, race, creed, color, religion, marital status, national origin, age, pregnancy, sexual orientation, gender, gender identity, gender expression, genetic information, disability, military status, status as a veteran, or any other protected characteristic We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know.

 

Senior DevOps Engineer - SecOps
CyberCoders -
Frederick, MD
IT SecOps Engineer
HatchPros -
Columbia, SC
Sr. SecOps Engineer
Motorola Solutions -
Texas, TX

For Employer
Looking for Real-time Job Posting Salary Data?
Keep a pulse on the job market with advanced job matching technology.
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

Sign up to receive alerts about other jobs with skills like those required for the SecOps Engineer III.

Click the checkbox next to the jobs that you are interested in.

  • SAP Asap Methodology Skill

    • Income Estimation: $151,672 - $199,860
  • Business Analytics Skill

    • Income Estimation: $113,296 - $161,817
    • Income Estimation: $123,752 - $161,465
This job has expired.
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Not the job you're looking for? Here are some other SecOps Engineer III jobs in the Toronto, ON area that may be a better fit.

SecOps Engineer

Robert Half, Bensalem, PA

SecOps Engineer - Airport

City of San Jose, San Jose, CA